IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads. |
| T1036.004 Masquerade Task or Service |
IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc. |
| T1053.005 Scheduled Task |
IronNetInjector has used a task XML file named |
| T1055 Process Injection |
IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process. |
| T1055.001 Dynamic-link Library Injection |
IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe. |
| T1057 Process Discovery |
IronNetInjector can identify processes via C# methods such as |
| T1059.006 Python |
IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector. |
| T1140 Deobfuscate/Decode Files or Information |
IronNetInjector has the ability to decrypt embedded .NET and PE payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.